Cyberattacks: Page 17


  • Johnson Controls logo above a production plant in Hanover, Germany.
    Image attribution tooltip
    Sean Gallup via Getty Images
    Image attribution tooltip

    Johnson Controls hit by ‘severe’ cyberattack

    The manufacturer of industrial control systems, security systems and HVAC equipment, said it’s still assessing what information was impacted.

    By Sept. 28, 2023
  • Rendered image depicting global networks.
    Image attribution tooltip
    DKosig via Getty Images
    Image attribution tooltip

    Progress Software says business impact ‘minimal’ from MOVEit attack spree

    While the company reported $951,000 in cyber incident and vulnerability response expenses for its third quarter, they represent just a sliver of its revenue.

    By Sept. 28, 2023
  • An exterior image of a hotel
    Image attribution tooltip
    Robert Mora via Getty Images
    Image attribution tooltip

    Caesars Entertainment faces class action lawsuits following rewards database hack

    At least four separate plaintiffs allege the company was negligent for allowing their sensitive personal data to be stolen in a social engineering attack by criminal threat groups. 

    By Sept. 27, 2023
  • Campbell Soup
    Image attribution tooltip
    Christopher Doering/Cybersecurity Dive
    Image attribution tooltip

    Campbell Soup says summer cyberattack caused limited business impact

    The company will incur some costs, but it considers the disruption nonmaterial.

    By Sept. 26, 2023
  • City skyline at sunset
    Image attribution tooltip
    dibrova via Getty Images
    Image attribution tooltip

    Royal lurked in Dallas’ systems weeks before ransomware attack

    The prolific threat actor gained initial access on April 7 and stole almost 1.2 TB of data before it deployed ransomware on May 3, city officials said in a post-attack report.

    By Sept. 25, 2023
  • Hotel Exterior
    Image attribution tooltip
    Ethan Miller via Getty Images
    Image attribution tooltip

    MGM Resorts warns customers of fraud as it faces class action lawsuits

    The plaintiffs claim the company was negligent for failing to protect customer data despite prior warnings about previous attacks.

    By Sept. 25, 2023
  • Sponsored by Specops Software

    Guard against SMS phishing in your organization

    How to Guard Against SMS Phishing In Your Organization with Secure Service Desk Verification.

    Sept. 25, 2023
  • Exterior of MGM Grand Hotel & Casino in Las Vegas
    Image attribution tooltip
    Ethan Miller via Getty Images
    Image attribution tooltip

    MGM Resorts says hotel, casino operations back up and running

    The company was still working to restore online functionality for hotel reservations and rewards program users following a major cyberattack.

    By Sept. 21, 2023
  • Bottles of Clorox bleach on a supermarket shelf.
    Image attribution tooltip
    Justin Sullivan via Getty Images
    Image attribution tooltip

    Clorox warns of product shortages a month after disclosing cyberattack

    The household product maker said the incident damaged IT systems and will have a material effect on its fiscal Q1 performance.

    By Sept. 18, 2023
  • An MGM Resorts sign
    Image attribution tooltip
    Ethan Miller via Getty Images
    Image attribution tooltip

    MGM, Caesars attacks raise new concerns about social engineering tactics

    Multiple threat groups have employed the same criminal tool kit to target vulnerable systems.

    By Sept. 18, 2023
  • Sponsored by Palo Alto Networks

    Decoding the complexities around Cloud Incident Response

    Unleash the power of the cloud with its countless advantages while staying ahead of cyber threats.

    By Ashlie Blanca, Consulting Director, Unit 42, Palo Alto Networks • Sept. 18, 2023
  • Hotel Exterior
    Image attribution tooltip
    Ethan Miller via Getty Images
    Image attribution tooltip

    Threat actors claim to have compromised MGM Resorts’ Okta environment

    AlphV may have used tactics similar to social engineering attacks disclosed by Okta in regulatory filing. 

    By Sept. 15, 2023
  • An exterior image of a hotel
    Image attribution tooltip
    Robert Mora via Getty Images
    Image attribution tooltip

    MGM Resorts disruption linked to recent attacks against hospitality industry

    Security researchers link the threat group Scattered Spider to a wave of malicious activity as Caesars Entertainment confirms social engineering attack in regulatory filing.

    By Sept. 14, 2023
  • An exterior image of a the Bellagio hotel in Las Vegas
    Image attribution tooltip
    Robert Mora via Getty Images
    Image attribution tooltip

    MGM Resorts discloses cyber incident in filing with SEC

    Moody’s Investors Service called the cyber incident credit negative, and MGM is still taking steps to protect data and fully secure business operations. 

    By Sept. 13, 2023
  • Password input field
    Image attribution tooltip
    Getty via Getty Images
    Image attribution tooltip

    Compromised credential use jumps 300% in cloud intrusions: IBM

    Valid credentials are also a hot commodity in the cybercrime marketplace, accounting for the vast majority, almost 90%, of assets for sale on the dark web, IBM found.

    By Sept. 13, 2023
  • Exterior of MGM Grand Hotel & Casino in Las Vegas
    Image attribution tooltip
    Ethan Miller via Getty Images
    Image attribution tooltip

    MGM Resorts takes systems offline as it investigates cyberattack

    The company restored full operations to dining, gaming and entertainment venues Monday night, following earlier reports payment systems, digital room keys and reservations systems were down at multiple properties. 

    By Updated Sept. 12, 2023
  • A jet comes in for landing at Los Angeles International Airport (LAX) in Los Angeles, California.
    Image attribution tooltip
    David McNew via Getty Images
    Image attribution tooltip

    Aviation sector organization hit by exploit of CVE duo

    Cybersecurity authorities investigated the attack by multiple threat actors who exploited known CVEs in Zoho and Fortinet products.

    By Sept. 8, 2023
  • A Microsoft logo is seen during the 2015 Microsoft Build Conference on April 29, 2015 at Moscone Center in San Francisco, California.
    Image attribution tooltip
    Stephen Lam via Getty Images
    Image attribution tooltip

    Microsoft crash dump exposed key that led to US cabinet email hacks, investigation finds

    A China-based threat group used the key to access a Microsoft engineer’s corporate account and, later, compromised more than two dozen customer email accounts.

    By Sept. 7, 2023
  • A signage of Microsoft in New York City
    Image attribution tooltip
    Jeenah Moon/Getty Images via Getty Images
    Image attribution tooltip

    BEC phishing kit hits thousands of Microsoft 365 business accounts

    Threat actors used the W3LL phishing kit to target more than 56,000 accounts, ultimately compromising 14% of them since last October, Group-IB found.

    By Sept. 7, 2023
  • Okta booth at RSA Conference on April 27, 2023 in San Francisco.
    Image attribution tooltip
    Matt Kapko/Cybersecurity Dive
    Image attribution tooltip

    Okta customers’ IT staff duped by MFA reset swindle

    IT workers at four organizations using Okta were successfully hit by a consistent pattern of social engineering attacks.

    By Sept. 6, 2023
  • Rendered image depicting global networks.
    Image attribution tooltip
    DKosig via Getty Images
    Image attribution tooltip

    Barracuda patch bypassed by novel malware from China-linked threat group

    Mandiant uncovered a months-long cyber espionage campaign targeting high value government entities and technology firms in the U.S. and abroad.

    By Sept. 1, 2023
  • An image of Federal Bureau of Investigation Director Christopher Wray at a press conference.
    Image attribution tooltip
    Kevin Dietsch/Getty Images via Getty Images
    Image attribution tooltip

    US leads takedown of Qakbot malware, which automated initial infections

    The botnet and malware had infected more than 700,000 computers worldwide and was linked to the abuse of OneNote files.

    By Aug. 30, 2023
  • Aerial view of a large crowd of people.
    Image attribution tooltip
    Dmytro Varavin/Getty Images via Getty Images
    Image attribution tooltip

    MOVEit attack victim count surpasses 1,000 organizations

    Months after the campaign was discovered, victims are still coming forward and, in most cases, breaches at third-party vendors are to blame.

    By Aug. 28, 2023
  • A stack of medical records displayed on a desk.
    Image attribution tooltip
    Alexandre Schneider/Getty Images via Getty Images
    Image attribution tooltip

    Prospect Medical stolen data listed for sale by emerging ransomware group

    Rhysida claims it stole more than 500,000 Social Security numbers, financial, legal and medical files. And it’s all for sale on the dark web.

    By Aug. 25, 2023
  • Matrix background of blurred programming code.
    Image attribution tooltip
    Getty Plus via Getty Images
    Image attribution tooltip

    Ransoming Linux and ESXi systems is getting easier

    Threat actors are using memory-safe languages to release payloads for Windows, Linux and ESXi simultaneously, SentinelOne researchers warn.

    By Aug. 24, 2023